Technology Governance Models for State Government
States are adopting hybrid IT governance models to balance central control with agency autonomy.

Congress hasn't passed a meaningful federal AI law, a federal privacy law, or much of anything else touching emergent tech, so states filled the vacuum. The Carnegie Endowment calls them "regulators of first resort," which is a polite way of saying nobody else showed up to do the job. State legislatures introduced more tech-related bills in 2025 than in any prior year, and the pace shows no sign of slowing. That legislative surge lands on top of internal governance structures that vary wildly from state to state, and this piece walks through what those structures look like, why they're shifting, and what happens when AI policy hits a system that wasn't built for it.
The three foundational models states use to organize internal technology authority
Picture state government IT as three different ways to run a kitchen. In one, a single head chef controls every recipe, every ingredient order, every staffing decision, and nobody touches the stove without sign-off. That's the centralized model: the state CIO's office runs most IT services, sets standards, owns security policy, and manages personnel across agencies. It's historically been treated as the gold standard structure, the one states graduate toward once they get their act together. Tighter cost control, more consistent security posture, cleaner procurement. The catch is that a health agency and a transportation agency have very different daily needs, and a single office trying to serve both can end up serving neither particularly well.
Now picture the opposite: every line cook runs their own station, orders their own ingredients, and answers to nobody but themselves. That's the decentralized model. Agencies keep their own IT shops, their own systems, their own support staff, and a central office (if one exists at all) sticks to policy guidance or oversight on the biggest projects rather than actual service delivery. Agencies get to move fast and build exactly what they need. But systems don't talk to each other, security practices drift apart depending on who's in charge that year, and the state ends up paying for the same software five different times under five different contracts.
The third option splits the difference on purpose. Hybrid, or federated, governance centralizes some functions (standards, security baselines, overall strategy) while leaving others (day-to-day service delivery, specialized systems) with the agencies. Sometimes this is the plan from day one; sometimes it's what a state looks like mid-transition, caught between where it used to be and where it's headed. California runs what it explicitly calls a "federated authority model," spreading strategic technology authority across the Governor's Office, executive agencies, and constitutional entities. Nevada's CIO put it more bluntly: "We're federated by design. We set statewide standards and let agencies innovate within them." That's a tidy way of admitting the state gave up on total control and decided that was fine, actually.
This isn't a new tension. It maps almost exactly onto the corporate-versus-divisional IT debate that's played out in large enterprises for decades, where corporate IT sets the rules and divisional IT fights for the exceptions. Frameworks like COBIT and ITIL, born in the private sector, describe the shapes these structures can take. What they don't do is tell a state legislature how to make any of it function inside a government culture with elected officials, term limits, and budget cycles that don't care whether your IT framework is theoretically sound.
How decision-making authority, accountability, and coordination differ across the three models
Here's where the three models stop being abstract org charts and start determining who actually picks up the phone when something breaks. Under centralized authority, the state CIO has final say on standards, procurement, and staffing. Accountability sits in one place, which sounds appealing until that one place becomes the reason nothing moves quickly. A single office reviewing every agency's technology request is, structurally speaking, a bottleneck waiting to happen. Agencies whose needs go unmet long enough tend to find workarounds, and workarounds are how shadow IT gets born.
Decentralized authority flips the accountability question into something closer to a shrug. Agencies own their decisions, which means no single office can be held responsible when something goes wrong statewide. Coordination becomes expensive because interoperability has to be negotiated agency to agency rather than declared from the top. Ask a state with a fully decentralized model to explain its overall security posture and you'll likely get a patchwork answer, because the honest answer is that there isn't one overall posture. There are dozens of them, running in parallel, occasionally colliding.
Hybrid and federated models try to thread the needle: the central CIO sets policy and minimum standards, agencies keep discretion inside those lines. Accountability splits cleanly on paper, standards belong to the center, implementation belongs to the agency, but that clean split requires constant upkeep. Oversight councils, shared frameworks, interagency working groups: these aren't nice-to-haves, they're the plumbing that keeps the split functional. Skip the maintenance and you get ambiguity about who actually owns a given decision, which is its own kind of paralysis.
All three models run into the same complication now: state CIO tenure averages just above two years, according to NASCIO's 2025 survey. Two years is barely enough time to learn where the bathrooms are in a large bureaucracy, let alone reshape how authority flows through it. A governance structure designed around a long-tenured CIO who understands every informal relationship in the building doesn't survive well when that CIO leaves every twenty-four months. So the real question underneath all three models isn't which one is smartest on a whiteboard. It's where a state wants its risk to sit: concentrated at the center, spread across agencies, or negotiated somewhere in the middle through formal coordination that has to be actively maintained rather than assumed.
Why states have trended toward hybrid structures rather than full centralization
Starting from a mid-2010s baseline, a good number of states restructured their IT setups, and the general direction of travel was toward more centralization. But full centralization never became the destination everyone landed on. Instead, a sizable group of states moved into, or stayed in, hybrid arrangements: Alabama, Arkansas, California, Florida, Georgia, Iowa, Kansas, Kentucky, Mississippi, and Montana all show up in research tracking these structural shifts over time.
Brookings research adds a wrinkle worth sitting with: centralizing strategy and IT personnel management in the CIO's office correlates with higher IT performance, but full decentralization correlates with lower performance. That's not the same as saying more centralization is always better; it's saying total fragmentation tends to hurt, while some coordination at the top tends to help. The finding lands in the space between the two extremes, which is exactly where hybrid models live.
Why does hybrid keep winning out over pure centralization, given that centralization theoretically offers tighter control? Agency need. A health department managing sensitive patient data and a transportation department managing traffic sensors and toll systems are not solving the same technical problems, and forcing them through identical processes wastes the specialized expertise each one actually needs. A more flexible structure lets a state put the right technical skills where they're actually needed instead of forcing every agency through the same funnel.
The Center for Technology and Government at University at Albany frames this as a matter of fit rather than ideology: the size of a state's government, its institutional history, its political priorities, all of it shapes which structure makes sense. No design wins across the board. So the practical question a state should ask isn't which model is objectively best; it's which model matches what this state's agencies, budget, and politics actually look like. That reframe (fit over ideal) is the same one that ends up mattering most once AI governance enters the picture.
What state CIOs say their governance structures must handle right now
NASCIO's Top 10 list, now in its twentieth year and built from responses across all 51 state and territory CIOs, put AI, generative AI, and agentic AI at number one for 2026. That's a first. Cybersecurity had held that top spot for twelve straight years before AI knocked it down to number two. The rest of the top five: budget and cost control, modernization, and digital government and digital services.
Worth pausing on the fact that consolidation and optimization crept back onto the list. That's not a technology adoption question, it's a structural efficiency question, and its return suggests CIOs are re-examining whether their current setup is actually the right shape, not just whether they've bought the right software. Budget and cost control ranking this high isn't surprising once you remember that governance model choice has direct dollar consequences: decentralized IT tends to run more expensive because of duplicated systems and contracts, while centralized IT demands real upfront investment before any savings show up. Accessibility climbing the list, meanwhile, signals that equitable service delivery is getting treated as a governance responsibility rather than a box to check during an audit.
And then there's tenure again, hovering just above two years on average. Most of the CIOs answering this survey inherited the governance structure they're now trying to steer, rather than building it themselves. That compresses how much time anyone has to make real structural changes before they're gone and someone else inherits their inheritance. Put the whole list together and you get a governance environment squeezed from three directions at once: new technology arriving faster than policy can process it, budgets tightening, and leadership turning over before either problem gets fully addressed. Whichever model a state runs, that's the pressure it's running under.
How states are building AI governance inside existing IT structures
Start with the number that makes casual, ad hoc AI governance impossible: 82 percent of employees inside state CIO organizations now use generative AI tools in their day-to-day work, per NASCIO's 2025 survey. That's not a pilot program or an experiment happening in a corner office. That's most of the workforce, which means governance has to catch up to behavior that's already widespread rather than trying to get ahead of behavior that hasn't started yet.
Most states have responded. Eighty-eight percent have some combination of AI responsible-use policies, flexible guardrails, security policies, or ethics requirements in place, according to the same NASCIO survey. Eighty-four percent are actively inventorying and documenting where AI shows up across agencies and applications. A large majority have stood up advisory committees or task forces, which sit in an interesting structural middle ground: not a top-down mandate from the CIO, not agencies figuring it out alone, but a dedicated body built specifically to handle the cross-cutting mess AI creates.
There's a useful parallel in how states already handle cloud computing. Every state now runs a hybrid cloud environment, and in federated states, agencies keep autonomy over which SaaS products they buy while operating inside centrally set frameworks. Several states have built cloud centers of excellence, essentially shared expertise hubs, as a coordination mechanism that doesn't require centralizing every decision. Texas took a different structural route for AI specifically: its 2024 legislature created an AI advisory council, which is a legislative body building a new oversight layer rather than routing that authority through the CIO's office. Structurally, that's its own category, separate from anything the executive branch built on its own.
The hard question underneath all of this: AI doesn't respect agency boundaries. It touches health, transportation, benefits administration, and everything else at once, so which governance model handles that best? Centralized governance can mandate uniform policy fast, but the CIO's office almost certainly doesn't have deep domain knowledge in Medicaid fraud detection and highway maintenance scheduling simultaneously. Federated governance lets each agency tailor AI oversight to its own domain, but that invites inconsistency and leaves gaps between agencies that nobody's watching. The emerging answer, based on what states are actually building, looks like hybrid governance with advisory councils bolted on: central standards for the baseline, domain-specific task forces for the parts that actually require specialized judgment.
Three models states use to govern AI at the legislative level
Many hundreds of AI-related bills got introduced across state legislatures between 2023 and 2025, and sorting through them reveals three distinct legislative strategies, not just fifty different flavors of the same law.
The first treats AI regulation as consumer protection, full stop. Colorado's AI Act, signed in 2024, stands as the most far-reaching state-level AI law in the country. It targets developers and deployers of high-risk AI systems across decisions that materially affect people's lives: education, employment, healthcare, housing, legal services. Compliance kicks in mid-2026. California took a narrower swing with SB 53, signed in September 2025, which focuses specifically on frontier AI model developers and leans on transparency requirements rather than prescriptive safety mandates. That's a deliberately smaller bill, following Governor Newsom's veto of the more sweeping SB 1047 the year before, a sign that California recalibrated scope rather than abandoning the effort.
The second approach treats AI governance as an economic development question first. Texas's TRAIGA, signed in June 2025 and effective this January, points its strongest requirements at state agencies rather than private companies, and it builds liability around intent rather than impact. That's a deliberate sequencing choice: govern how government uses AI before wading into how the private sector uses it.
The third approach treats governance as an experiment rather than a rulebook. Utah's Artificial Intelligence Policy Act, signed in March 2024, set up an Office of Artificial Intelligence Policy alongside a "Learning Laboratory" program that offers developers temporary regulatory relief in exchange for participating in structured testing. Governance here isn't primarily about compliance; it's about learning what needs governing before locking anything in.
There's a real connection back to how these states run their internal IT. States with centralized CIO authority tend to move faster issuing uniform internal AI mandates, since one office can simply decide and enforce. States with federated models may actually find legislative AI governance easier to implement, since their agencies are already used to managing their own compliance inside broad state frameworks; the muscle memory's already there. And 2025 brought a broader shift worth flagging: legislatures pulled back from sweeping algorithmic discrimination bills and moved toward narrower transparency and disclosure rules instead, a sign that lawmakers are calibrating scope around what's actually enforceable rather than what sounds comprehensive on paper.
The federal-state tension that now shapes every state's governance choices
In January 2025, the Trump administration issued Executive Order 14179, revoking Biden-era AI safety requirements and directing federal agencies to clear away barriers to AI adoption. That was a signal about where federal priorities sat, and it wasn't subtle.
The December 2025 order went considerably further. It created an AI Litigation Task Force specifically to challenge state AI laws, directed the Commerce Department to identify which state laws conflict with federal objectives, and floated conditioning federal funding on state compliance. That's not a signal anymore; that's pressure with teeth. Three areas got explicitly carved out from preemption, though: child safety in AI contexts, AI compute and data center infrastructure, and state government procurement of AI systems. That third carve-out matters a great deal for this piece specifically, because it directly protects a state's authority to govern how its own agencies buy and deploy AI, regardless of what happens with private-sector rules.
Congress, notably, did not pass a proposed moratorium on new state AI laws. So states retain their legal authority here; what they're facing instead is executive-branch pressure without statutory backing. That distinction matters. It means the fight is playing out through litigation and funding leverage rather than through Congress simply overriding state law.
Here's the governance angle worth sitting with: states with strong centralized CIO authority and documented internal AI governance frameworks are better positioned to defend themselves if this escalates, because they can point to a single, coherent policy rather than fifty agencies each doing something slightly different. A state that can say "here is our framework, here is how it applies uniformly" has a cleaner story to tell than a state whose agency-level AI decisions vary so widely that nobody could summarize the state's actual position in one sentence. Federated and decentralized states face more exposure here, not because their governance is necessarily worse, but because inconsistency is harder to defend when someone in Washington starts asking pointed questions.
What determines whether a governance model actually performs well under pressure
Strip away the acronyms and the org charts, and the research keeps landing on the same conclusion: the specific model matters less than how well it fits the state running it. The Center for Technology and Government's framing holds up here too. Size of government, institutional history, political priorities, these determine fit far more than which label sits on the org chart.
Three things separate governance structures that hold up under pressure from ones that buckle, and none of them depend on picking the "correct" model. Clarity of authority comes first: ambiguity over who owns a decision, the CIO or the agency, is the single most common failure mode inside hybrid and federated structures. Coordination mechanisms come second: advisory councils, cloud centers of excellence, interagency working groups. These aren't decorative add-ons to hybrid governance; they're the load-bearing walls. Remove them and the whole structure sags. Leadership continuity comes third, and it's the hardest one to engineer around. With CIO tenure sitting just above two years, governance has to live in documented frameworks and written policy rather than in the relationships one CIO happened to build during their brief run.
AI is currently the stress test running on all fifty states at once, and it's an unforgiving one. Adoption climbed sharply in a single year, which means any governance model that requires slow, careful consensus-building before it acts is going to fall behind the behavior it's supposed to be governing. The federal pressure test runs in parallel, rewarding states that can point to coherent, unified governance over states whose agencies each tell a slightly different story. That favors at least some centralization of policy, even inside a federated model, because a state needs one clear voice when someone in Washington comes asking who's actually in charge. Whether that voice sits with a CIO who's been in the job two years or twenty is, apparently, a separate problem entirely.


